logo

Compromised Browser Extensions - A Growing Threat Vector

ID: bdc18cb9-0c71-53ab-957c-674e82d1507e

STIX ID: report--bdc18cb9-0c71-53ab-957c-674e82d1507e

Feed Name: Pulsedive Blog

Threat Score
75/100

Date Published: 2025-02-25

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

This report documents a January 2025 campaign where a targeted phishing supply-chain attack compromised dozens of Chrome extensions (notably Cyberhaven and GraphQL Network Inspector), impacting an estimated 2.6 million users; malicious updates added service-worker and content-script logic to fetch C2 configurations and exfiltrate data (targeting Facebook and ChatGPT-related pages), while other extensions and families like Rilide acted as information stealers. The report includes lists of compromised extension IDs and versions, malicious JavaScript samples and decoded configurations, analysis findings (Booz Allen/Sekoia), and mitigation recommendations for home users and corporate IT (extension permission review and Intune/Defender controls).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.